7.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Description
Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
Basic Information
ID
CVE-2025-64134
Source
jenkins
Published
Oct 29, 2025 at 13:29
Modified
Oct 29, 2025 at 14:08
Affected Product
Vendor
Jenkins Project
Product
Jenkins JDepend Plugin
Affected Versions
Jenkins Project Jenkins JDepend Plugin 0